Repository navigation
Conversation
❌ 5 Tests Failed:
View the top 3 failed test(s) by shortest run time
To view more test analytics, go to the Test Analytics Dashboard |
ebursztein
added a commit
that referenced
this pull request
Oct 7, 2026
Link assigned issue #342 and source PRs #338, #339 and #340. Keep completed parser components available while removing Inspect VM/workload and Dockerfile/Compose phases from this agent sprint. Shared 0.7 includes all carried code and latest main; complete integration and runtime/package qualification remain Pierre’s work.
…ration Port the inspect-capsem Inspect AI SandboxEnvironment integration onto the 0.7 Python SDK surface in VM-only mode (container/image execution deferred to the follow-up container commit): - Split the implementation across focused modules under integrations/inspect-ai/inspect_capsem/ (config.py, _controller.py, _exec.py, _files.py, _lifecycle.py, _registry.py, _tools.py, _transfer.py, sandbox.py) with every module under 300 lines at 100 columns. - Encapsulate private CapsemSandboxEnvironment state inside sandbox.py, return SandboxConnection(type="capsem", command="capsem shell <id>"), and bound process-owned VM teardown at interpreter exit. - Derive staged file transfer part sizes from MAX_REQUEST_BODY_BYTES, scope VM cleanup to exact managed-by + prefix labels, and clean up unnamed VMs on 504 CreateTimeoutError via CreateTimeoutError.vm_id. - Harden non-root user environment reset when id -un prints numeric UID to stdout and exits 1 or pwd.getpwuid raises KeyError in minimal containers. - Wire integrations/inspect-ai into capsem-gate, CI scope routing, installed wheel/sdist entry-point proof (image_package_acceptance.py), and live VM ironbank acceptance (live_acceptance.py + test_sdk_live.py). Proves #310 / #342 acceptance criteria: - [x] `inspect_capsem` registers cleanly as an `inspect_ai` `SandboxEnvironment` entry point (`@sandboxenv(name="capsem")`) from an installed `inspect-capsem-sandbox` wheel and sdist in an isolated prefix (`integrations/inspect-ai/tests/image_package_acceptance.py`). - [x] `sample_init`, `exec` (`ExecTarget.VM` with non-zero exit, signal, and timeout), `read_file`/`write_file` (text, binary, non-workspace), Inspect's `self_check` suite, `eval_async` with `SandboxEnvironmentSpec("capsem", ...)`, `sample_cleanup`, `task_cleanup`, and prefix-scoped `cli_cleanup` run against the live service with session ledger (`history(layer=EXEC)` + `session.db` `exec_events`) and zero leaked VMs.
tholop
force-pushed
the
feat/sdk-typed-helpers
branch
from
October 8, 2026 13:07
c1ff8c7 to
cb10270
Compare
tholop
force-pushed
the
feat/inspect-capsem
branch
from
October 8, 2026 13:07
6f9656f to
8708553
Compare
This was referenced Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
inspect-capsemInspect AISandboxEnvironmentintegration (@sandboxenv(name="capsem")inintegrations/inspect-ai, distributioninspect-capsem-sandbox, moduleinspect_capsem) onto the0.7Python SDK surface in VM-only mode (superseding the monolithic feat(inspect-ai): add inspect-capsem SandboxEnvironment integration #291 PR; upstream tracking issue 0.7: Refactor and land Inspect VM/workload support #310).integrations/inspect-ai/inspect_capsem/(__init__.py,config.py,_controller.py,_exec.py,_files.py,_lifecycle.py,_registry.py,_tools.py,_transfer.py,sandbox.py), with every module under 250 lines at 100 columns.persistent=False, labeledmanaged-by=inspect-capsem+ optionalinspect-capsem-prefix/inspect-capsem-task) and scopestask_cleanup/cli_cleanupstrictly to matching labels.capsem>=0.7.0): usesHypervisor.connect/discover_gateway, typedVmNotFoundError/CreateTimeoutError/ExecTimeoutError(cleaning up unnamed VMs on HTTP 504CreateTimeoutErrorviaCreateTimeoutError.vm_id), andVmLifecycleState.MAX_REQUEST_BODY_BYTES, enforcesSandboxEnvironmentLimits.MAX_EXEC_OUTPUT_SIZE(10 MiB per stream), requires[ -f ]and caps guest reads atlimit + 1bytes while streaming (head -c+ per-part accounting in_transfer._staged_download), after astatpre-check againstSandboxEnvironmentLimits.MAX_READ_FILE_SIZE.connection()returnsSandboxConnection(type="capsem", command="capsem shell <vm_id>").integrations/inspect-aito[boundary.scripts].roots(300-line ceiling), wires the package intocapsem-gate(fast.integrations.inspect-ai.{lint,types,tests,build}), CI scope routing, and the ironbank live VM lane (tests/ironbank/test_sdk_live.pyrunsintegrations/inspect-ai/tests/live_acceptance.py, assertingINSPECT_CAPSEM_VM_ACCEPTANCE_OK).Mapping to Elie's #291 Review
Every item from the #291 review, and where it is resolved in the stack:
integrations/not in[boundary.scripts].roots; 6 files over)integrations/inspect-aiadded toroots; VM-mode modules split by responsibility (largest:_lifecycle.py238,sandbox.py231). PR 3 / PR 4 modules also stay under the ceiling (compose_yaml.py253,image_build.py295,oci_registry.py294)._staged_downloadno byte cap,/dev/zero,_save_built_image_to_cache)_save_built_image_to_cachehalf in PR 3 / PR 4_files.read_guest_filerequires a regular file ([ ! -f ] -> NOT_REGULAR),_staged_downloadruns[ -f ] && head -c <limit+1> | splitand stops atlimit + 1while joining parts. The in-guest image cache that owned_save_built_image_to_cacheis deleted with the0.6dockerd backend (PR 3); PR 4's host-side ingestion writesdocker image save -o <tmp>/image.tarto disk and streams blobs in 256 KiB chunks (oci_registry.ingest_docker_save_tar), never reading the archive into memory.labels) + PR 2bpersistent=FalseVMs withmanaged-by=inspect-capsem.inspect-capsem-prefix")cli_cleanupandtask_cleanuponly stop VMs withmanaged-by=inspect-capsem(and the matchinginspect-capsem-prefixwhenCAPSEM_VM_PREFIXis set);inspect sandbox cleanup capsem <id>on any other VM logs a warning and leaves it alone.environment: [KEY], bind volumes)CAPSEM_INSPECT_ALLOWED_HOST_ENV/CAPSEM_INSPECT_ALLOWED_HOST_PATHS(operator env vars, not task config),os.path.realpathcontainment of bind sources. Not claimed by this PR.capsem>=0.6.3while using newer APIs)integrations/inspect-ai/pyproject.tomldeclarescapsem>=0.7.0— the first release that will containlabels,Hypervisor.connect,ErrorCode, andimage=. In-repo resolution uses[tool.uv.sources](editable../../sdk/python); thesdk/python/pyproject.tomlmanifest itself still reads0.6.3only because it is outside the[[versions.stamped]]release cohort (see PR 2a notes; bump tracked with #309).sanitize_file_path, error-text parsing)discover_gateway/Hypervisor.connect, structuredErrorResponse.code+ typed exceptions; PR 2b consumes them. Nosanitize_file_pathcopy remains — guest paths are validated server-side by0.7'sfiles.read/write(..., exact=...). Nore.searchover error text ininspect_capsem/.tests/ironbank/test_sdk_live.pyrunsintegrations/inspect-ai/tests/live_acceptance.pyin the VM lane without opt-in flags.X as Xre-exports inbuildschema.pyrefactor/0.7-qualification-schemas-draft(bb29556b, kept under Pierre's authorship); his follow-upba76171f(test_qualification_schema_reexports_keep_one_model_identity) assertsbuildschema.X is qualifyschema.X, i.e. the re-exports are now pinned by upstream's own test. Not changed in this stack — say the word if you still want them dropped and we will update that test alongside.8a146e35also addsSourcePackageConfig, only the next commit uses itbb29556bcarriesSourcePackageConfigandba76171ftests it (_source_package_type). PR 2b is the first consumer ([integrations_inspect_ai]inconfig/gate.toml).sdkchecks.pyinstead ofisinstance/ fallback branchessdkchecks.pytakessettings: SourcePackageConfigexplicitly; noisinstancefallback remains.assertin production code (sandbox.py)assertstatements ininspect_capsem/.refactor/0.7-qualification-schemas-draft; VM-mode sandbox -> PR 2b; container mode -> PR 3, with host-sideDockerfile/build:split further into PR 4 because it runsdocker buildon the host (its own trust-boundary caveat). SDK prerequisites -> PR 1 / PR 2a.ModulesConfig.transition: TransitionSettingsconflict inqualifyschema.py0.7qualifyschema.py:70on this stack (the stack is based onintegration/0.7-clients-inspect+ the two draft branches), so there is no conflict to resolve.Stack Overview (Supersedes #291)
feat/sdk-vm-labels) — VM labels on create, fork, and listfeat/sdk-typed-helpers) — structuredErrorCodeenum, timeout/lookup exceptions, and gateway discoveryfeat/inspect-capsem) (this PR) — VM-modeinspect-capsemSandboxEnvironmentintegrationfeat/inspect-capsem-containers) — OCI container execution mode and Compose parserfeat/inspect-capsem-host-build) — host-sideDockerfileand Composebuild:image support